logoalt Hacker News

losthobbiesyesterday at 9:52 PM1 replyview on HN

Sanitise input and LLM output.


Replies

chasd00yesterday at 10:17 PM

> Sanitise input

i don't think you understand what you're up against. There's no way to tell the difference between input that is ok and that is not. Even when you think you have it a different form of the same input bypasses everything.

"> The prompts were kept semantically parallel to known risk queries but reformatted exclusively through verse." - this a prompt injection attack via a known attack written as a poem.

https://news.ycombinator.com/item?id=45991738

show 1 reply